System Security & Firewall Management Flashcards
7 cards from real LCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Security & Firewall Management flashcards as text
Which firewalld zone is most appropriate for a highly trusted internal network interface?
Answer: trusted
The 'trusted' zone in firewalld accepts all connections and is designed for fully trusted networks.
What command permanently adds HTTP service to the active firewalld zone?
Answer: firewall-cmd --permanent --add-service=http
The --permanent flag ensures the rule persists across reboots; --reload is then needed to apply it.
Which SELinux command is used to change a file's security context permanently?
Answer: semanage fcontext
semanage fcontext adds a persistent policy rule, while chcon only changes the context temporarily.
What does the 'nmap -sS' scan type perform?
Answer: TCP SYN (stealth) scan
A SYN scan sends SYN packets and never completes the handshake, making it faster and less detectable than a full connect scan.
Which file configures system-wide PAM password quality requirements on RHEL-based systems?
Answer: /etc/security/pwquality.conf
pwquality.conf is read by the pam_pwquality module to enforce password complexity rules.
Which iptables target silently drops packets without sending any response?
Answer: DROP
DROP silently discards the packet, whereas REJECT sends an ICMP error back to the sender.
What is the purpose of the /etc/hosts.deny file in TCP Wrappers?
Answer: Denies access to specified hosts for wrapped services
TCP Wrappers checks /etc/hosts.allow first, then /etc/hosts.deny to determine whether to permit a connection.